Privacy Policy

Privacy Policy

This Privacy Policy sets out the rules for the processing of personal data of users of the website kacperkochan.dev, in performance of the information obligation under Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR").

Last updated: 1 August 2026Polska wersja →

General provisions

Administrator
Kacper Kochan - se7t.dev
NIP
5632445012
REGON
388994617
Registered address
Połaniecka 25/6, 22-100 Chełm, Poland

The Administrator of personal data within the meaning of Article 4(7) of the GDPR is the entity indicated above.

The Administrator has not appointed a Data Protection Officer. In all matters concerning the processing of personal data, contact should be made using the email address indicated above.

This Policy applies to the website available at kacperkochan.dev and to all personal data processed in connection with the use of that website.

Purposes, legal bases and retention periods

Personal data is processed for the following purposes:

a) Handling correspondence submitted through the contact form

Scope of data
Name, email address, selected subject of the message, and the content of the message
Purpose
Reviewing the content of the message and providing a reply
Legal basis
Article 6(1)(f) of the GDPR — the legitimate interest of the Administrator consisting in conducting correspondence addressed to the Administrator
Retention period
3 years from the date of the last correspondence

b) Verifying that the contact form is not being completed by automated means

Scope of data
IP address and technical information concerning the user's browser
Purpose
Distinguishing a user from automated software, in order to prevent abuse of the contact form
Legal basis
Article 6(1)(f) of the GDPR — the legitimate interest of the Administrator consisting in counteracting abuse and maintaining the functionality of the contact form
Retention period
For the period necessary to achieve the purpose indicated above, determined by the retention cycle for logs and verification data applied by Cloudflare, Inc. as the processor

c) Ensuring the security and availability of the website

Scope of data
IP address, date and time of the request, technical information transmitted by the browser, and the content of the cookie referred to in section 7
Purpose
Delivering the content of the website, limiting the number of requests originating from a single IP address, distinguishing a browser operated by a person from automated software, and ensuring the security and correct operation of the website
Legal basis
Article 6(1)(f) of the GDPR — the legitimate interest of the Administrator consisting in ensuring the security and correct operation of the website
Retention period
For the period necessary to achieve the purpose indicated above, determined by the retention cycle for logs and verification data applied by Cloudflare, Inc. as the processor

Voluntary nature of providing data

Providing personal data is voluntary. Providing a name, an email address and the content of the message is, however, a condition for submitting the contact form. Failure to provide that data prevents the message from being sent and a reply from being given.

Recipients of personal data

Personal data may be disclosed to the following recipients:

Cloudflare, Inc. (USA)
Hosting of the website, the anti-spam verification mechanism, and delivery of messages sent through the contact form
Proton AG (Switzerland)
Operation of the email account to which those messages are delivered

Cloudflare, Inc. processes data on behalf of the Administrator as a processor within the meaning of Article 28 of the GDPR, under a data processing agreement concluded with that entity. Proton AG provides the email service to the Administrator and processes the data contained in the messages delivered to that mailbox to the extent necessary to provide that service, on the terms set out in its own terms of service and its own privacy policy.

Personal data is not sold, is not disclosed for marketing purposes, and is not made available to any other entities, except where the obligation to disclose it arises from generally applicable provisions of law.

Transfers of data to third countries

Cloudflare, Inc. has its registered office in the United States of America. Transfers of personal data to that entity take place on the basis of the European Commission's adequacy decision in respect of the EU–US Data Privacy Framework (Article 45 of the GDPR) and, in addition, on the basis of the standard contractual clauses referred to in Article 46(2)(c) of the GDPR, incorporated into Cloudflare's data processing addendum.

Owing to the distributed nature of the network operated by that entity, data may also be processed in other countries in which that entity maintains its infrastructure; such transfers are covered by the safeguards indicated above. A copy of the standard contractual clauses may be obtained at the following address:

Proton AG has its registered office in the Swiss Confederation, in respect of which the European Commission has determined that an adequate level of protection of personal data is ensured, in accordance with Article 45 of the GDPR. The application of additional safeguards is not required in that case.

Rights of the data subject

The data subject has the right to:

  • access their personal data and obtain a copy of it (Article 15 of the GDPR);
  • obtain rectification of personal data which is inaccurate (Article 16 of the GDPR);
  • obtain erasure of personal data (Article 17 of the GDPR);
  • obtain restriction of processing of personal data (Article 18 of the GDPR);
  • object to the processing of personal data carried out on the basis of the legitimate interest of the Administrator (Article 21 of the GDPR).

The Administrator separately draws attention to the right to object: as every processing operation described in this Policy is based on Article 6(1)(f) of the GDPR, the data subject may object at any time, on grounds relating to their particular situation, to the processing of their personal data. Upon receipt of an objection the Administrator will no longer process the data concerned, unless the Administrator demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims (Article 21(1) of the GDPR).

The above rights are exercised on the basis of a request sent to the email address indicated in section 1. The Administrator provides a response without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, by reason of the complexity of the request or the number of requests; the Administrator informs the data subject of any such extension, together with the reasons for the delay, within one month of receipt of the request (Article 12(3) of the GDPR).

The data subject additionally has the right to lodge a complaint with the supervisory authority:

Authority
Prezes Urzędu Ochrony Danych Osobowych
Address
ul. Stanisława Moniuszki 1A, 00-014 Warszawa

Cookies and terminal equipment

The website uses one cookie, described below. Apart from that cookie, the website does not store information on, and does not gain access to information already stored in, the user's terminal equipment.

Name
cf_clearance
Set by
Cloudflare, Inc. — the entity indicated in section 4 — as part of the mechanism designated by that provider as JavaScript Detections. The cookie is stored under the domain kacperkochan.dev and is read only by that domain.
Purpose
Recording the result of an automated check of whether a request originates from a browser operated by a person rather than from automated software, for the purpose and on the legal basis indicated in section 2(c)
Scope of application
Every page of the website. The mechanism operates at the level of the infrastructure provider and is not limited to the contact form
Storage period
Short-lived; the expiry is set by Cloudflare, Inc. and the cookie is issued again on subsequent visits

That cookie does not serve analytical, advertising or tracking purposes. It is not used to identify the user on any other website, its content is not combined with data from any other source, and no marketing profile is created on its basis.

In the assessment of the Administrator, storing that cookie is strictly necessary in order to provide the service explicitly requested by the user, and is therefore covered by the exemption from the consent requirement provided for in the provisions of the Electronic Communications Law implementing Article 5(3) of Directive 2002/58/EC. For that reason the website does not present a consent request. Should that assessment change, this Policy will be amended and the user's consent obtained before the cookie is stored.

The contact page loads the anti-spam verification mechanism referred to in section 2(b) from the domain challenges.cloudflare.com, including its subdomains, which is operated by Cloudflare, Inc. Displaying and operating that mechanism causes the user's browser to connect to that domain and to transmit to it the data indicated in section 2(b). That processing is carried out by the entity indicated in section 4, on the terms set out in sections 4 and 5.

No other page of the website loads resources from a domain other than its own. Typefaces, style sheets and scripts are served from the website's own domain, as is the script of the mechanism described in the table above, although that script originates from the provider indicated there. The website in its entirety, including those resources, is delivered through the content delivery network of the entity indicated in section 4, which is the hosting of the website referred to in that section.

The website does not store data in the browser's local storage (localStorage, sessionStorage).

Automated decision-making and profiling

Personal data is not subject to automated decision-making, including profiling, as referred to in Article 22 of the GDPR.

The Administrator does not use analytical, advertising or tracking tools, and does not combine data collected through the website with data from any other source.

Security of processing

The Administrator applies technical and organisational measures appropriate to the risk of infringement of the rights and freedoms of data subjects, in accordance with Article 32 of the GDPR.

In particular, data transmitted between the user's browser and the server is encrypted using the TLS protocol, and the contact form endpoint is subject to a limit on the number of requests originating from a single IP address.

Amendments to the Policy

The Administrator reserves the right to amend this Policy. The date of the last amendment is indicated at the beginning of the document.

Amendments of a purely editorial nature which do not affect the rules for the processing of personal data do not result in a change to that date.